CVE 4.8 MEDIUM

Yeelink Yeelight App com.yeelight.cherry AndroidManifest.xml improper export of android application components_CVE-2025-8210

4.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component com.yeelight.cherry. The manipulation leads to improper export of android application components. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-8210
Source VulDB
Published Jul 26, 2025 at 20:32
Modified Jul 28, 2025 at 15:15

Affected Product

Vendor Yeelink
Product Yeelight App
Version 3.5.0
Affected Versions Yeelink Yeelight App 3.5.0
Yeelink Yeelight App 3.5.1
Yeelink Yeelight App 3.5.2
Yeelink Yeelight App 3.5.3
Yeelink Yeelight App 3.5.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.